URLhaus Database

You are currently viewing the URLhaus database entry for http://paymentadvisry.com:8088/scripts/Receipt-427172.xls?tmudq=0if2ff1WeN9lRJR which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1454674
URL: http://paymentadvisry.com:8088/scripts/Receipt-427172.xls?tmudq=0if2ff1WeN9lRJR
URL Status:Offline
Host: paymentadvisry.com
Date added:2021-07-14 19:07:04 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-14 19:08:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 18 hours, 6 minutes Poor (down since 2021-07-16 13:14:15 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc 4b4cc1a76e1a4490106276a68f6a3b81e28693c9946fa8ab0e38d610cb2e2e01n/a 
2021-07-16n/adoc 8b48ecc28fcab629dd18dfb2f9ef787669b85f035cd73960a3a897271dc778dfn/a 
2021-07-16n/adoc c8ab8f4b5b9ff142a9cf4e6810c85b990a2ac253e82227b1b7496ac5993ebbb6n/a Dridex
2021-07-16n/adoc eac79f6c752bc33d8b0b5d643737c3e3d4de33fe705844404b584bd70b620537n/a 
2021-07-15n/adoc 19670f9153974c5ca0f866b19d356b9be253ff54812ada0a5d733240e6dc3031n/a 
2021-07-15n/adoc 07d340e840894c8b5f72e0db886e6a38f18f0920dd90b5fd376a4bad442d1746n/a Dridex
2021-07-14n/axls cdcc50360daab3bda1f658df5d13f1c205c64cc628a06d4e887fecd84d7c7fcdVirustotal results 29.03%Dridex